Re: Start up problem. Hangs. No entry in sys tray except time



Hi,
Thanks again for the response.
I tried ProcessExplorer. Its really a good software but it didnt not solve
my problem. I Meanwhile observered something very strage.
I tried cleaning again using Avira Antivir. it detected 9 more torajans.!!
I restarted my sytem 4-5 times cleanly but again i got the same problem (now
it shows some icons in systray though). I again ran AntiVir it again detected
and deleted some more tojans. (This time 7). Same procedures I followed 4-5
times. I am able to start system cleanly for for 4-5 times. Then again
missing icons in system tray. I log off and logg in again , run Antvir it
again detects 7-8 trojans.
It appears that these trojan appear again after some reboots. Hows that
possible?
Is it some self reproducing virus or something? These are detected in
C:\System Volume Information directory.
(In last scan I chose to move them to quarantine rather deleting them)

Follwoing is part of the AntiVir scan report.
C:\System Volume Information\MountPointManagerRemoteDatabase
[WARNING] The file could not be opened!
C:\System Volume
Information\_restore{8C459B98-89AA-45F6-A5B9-323014416103}\RP90\A0027802.exe
[DETECTION] Is the Trojan horse TR/Dldr.FFZ.33
[INFO] The file was moved to '44730505.qua'!
C:\System Volume
Information\_restore{8C459B98-89AA-45F6-A5B9-323014416103}\RP90\A0027821.exe
[DETECTION] Is the Trojan horse TR/Dldr.FFZ.33
[INFO] The file was moved to '40a3ec5e.qua'!
C:\System Volume
Information\_restore{8C459B98-89AA-45F6-A5B9-323014416103}\RP90\A0027840.exe
[DETECTION] Is the Trojan horse TR/Dldr.FFZ.33
[INFO] The file was moved to '44730506.qua'!
C:\System Volume
Information\_restore{8C459B98-89AA-45F6-A5B9-323014416103}\RP90\A0027859.exe
[DETECTION] Is the Trojan horse TR/Dldr.FFZ.33
[INFO] The file was moved to '44730507.qua'!
C:\System Volume
Information\_restore{8C459B98-89AA-45F6-A5B9-323014416103}\RP90\A0027878.exe
[DETECTION] Is the Trojan horse TR/Dldr.FFZ.33
[INFO] The file was moved to '40a3ec50.qua'!
C:\System Volume
Information\_restore{8C459B98-89AA-45F6-A5B9-323014416103}\RP90\A0027897.exe
[DETECTION] Is the Trojan horse TR/Dldr.FFZ.33
[INFO] The file was moved to '44730508.qua'!
C:\System Volume
Information\_restore{8C459B98-89AA-45F6-A5B9-323014416103}\RP90\A0027916.exe
[DETECTION] Is the Trojan horse TR/Dldr.FFZ.33
[INFO] The file was moved to '44730509.qua'!
C:\System Volume
Information\_restore{8C459B98-89AA-45F6-A5B9-323014416103}\RP90\A0027935.exe
[DETECTION] Is the Trojan horse TR/Dldr.FFZ.33
[INFO] The file was moved to '40a3ec52.qua'!



"Thota Umesh" wrote:

Thanks, you are welcome, when using onecare you were not able to connect
internet probably due to firewall settings if u are going to use antivir i
suggest u to have windows defender installed. regarding ur startup issue i
suggest to check the processes that are running using process explorer that
way u can analize which application or process is causing the delay. here's
the url : www.sysinternals.com/Utilities/ProcessExplorer.html
ps: the process using most of cpu are marked with red background.
Hope this helps...,

Happy Easter
Umesh Thota
www.windowsworkshop.com.

"Sushil" <Sushil@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DF2F3300-A856-41A0-86B1-66B7F2C406AB@xxxxxxxxxxxxxxxx
Well u r in concluding that my laptop still infacted. I installed
windowsonecare first which removed 2 trojans. But I could not connect with
internet anymore. I tried many times. Checked all the setting but could
not
make out anything. Finally I uninstalled it and I could get the internet
access again. Then I installed "Avira Antivir" from www.freeav.com. This
anti
virus looks prett y good. It detected 36 trojans, while other antivirus
could
detect only 1 or two or none. Thanks for suggesting this.

My problem is still same. sometime when I startup the system I face same
problem as I mentioned melow.
Thank you for the response anyway.
--
Sushil Kumar


"Thota Umesh" wrote:

Hii, you are still infected use a good antivirus and antispyware scan
www.windowsonecare.com or www.freeav.com both are very good! antivirus
softwares & get windows defender here
[www.microsoft.com/athome/security/spyware/software/default.mspx] if you
have installed windows onecare it shd install defender automatically.

"Sushil" <Sushil@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:7FF228EA-FE01-4DD9-9360-D18577376250@xxxxxxxxxxxxxxxx

Hi All,
Whenever I start my XP, most of the time (not always) windows (sort of)
hangs. No entry except time is display in system tray. I cant open
anything
thogh I can move my mouse. If I long off and login generally problem
gets
resolved.
Note that this problem started after my PC got addwares like Torjan
horse
and Trojan.favadd.
Though later I removed these addwares using norten anti virus. But this
problem is still continued.

Please help me to resolve this problem.
--
Sushil Kumar









.



Relevant Pages

  • Re: got this trojan in a file called mscmsr.dll - dont know where it came from...
    ... | Archive type: CAB (Microsoft) ... | [DETECTION] Is the Trojan horse TR/Agent.AHDK.1 ...
    (microsoft.public.security.virus)
  • Re: HEUR / malware??
    ... But I still like Antivir because after you send the False Positive ... Files, they will take away the detection in a short time, 2-3 days, ... heuristic detection for free from antivir to detect unknown virus. ... you restore your system to those restore points, ...
    (alt.comp.anti-virus)
  • Re: HEUR / malware??
    ... But I still like Antivir because after you send the False Positive ... Files, they will take away the detection in a short time, 2-3 days, ... heuristic detection for free from antivir to detect unknown virus. ... you restore your system to those restore points, ...
    (alt.comp.anti-virus)
  • Re: HEUR / malware??
    ... But I still like Antivir because after you send the False Positive ... Files, they will take away the detection in a short time, 2-3 days, ... heuristic detection for free from antivir to detect unknown virus. ... you restore your system to those restore points, ...
    (alt.comp.anti-virus)
  • Re: ISP notification, with virus
    ... machine or not without knowing what Trojan horse was detected. ... Microsoft "MVP" - Windows Security ... then my virus detection detected a trojan ...
    (microsoft.public.security.virus)